Methods for insuring resilience

Appraise some recommendations by authorities (such as NIST, Carnegie Mellon, DHS) for insuring Cybersecurity Resilience -- which of those recommendations by authorities also include suggestions to test to verify the chosen methods for insuring resilience?